ZeroFox Cyber Intelligence Daily Brief - March 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 12, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics
- French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
- Okta Says Data Leaked on Hacking Forum Not From Its Systems
New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics
A new banking trojan called CHAVECLOAK is targeting users in Brazil through phishing emails containing PDF attachments. The phishing emails use DocuSign lures related to contracts to trick users into opening the PDF files, which contain a button to read and sign the documents. However, clicking the button triggers the retrieval of an installer file from a remote link shortened using the Goo.su URL shortening service.
French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
On March 11, the French government said that a cyberattack of “unprecedented intensity” had targeted several of its services, prompting the activation of a special crisis center to restore online services. A statement from Prime Minister Gabriel Attal’s office further added that the attack had struck multiple ministries. By Monday afternoon, the attack’s impact had been reduced, restoring several impacted services and sites. ZeroFox has observed threat actor group Anonymous Sudan take responsibility for targeting the French government in denial-of-service attacks. The threat actor has particularly named the French Interministerial Directorate of Digital Affairs as its victim.
Okta Says Data Leaked on Hacking Forum Not From Its Systems
Okta denies any involvement in the alleged data leak shared by a threat actor on a hacker forum. According to a spokesperson, the data does not belong to the company and appears to be sourced from public information on the internet. The spokesperson emphasized that the leaked data is not associated with the October 2023 security incident where Okta's support system was breached, leading to the theft of cookies and authentication for some customers. The company conducted an internal investigation in November, revealing that the incident affected all users of the customer support system.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Ddarknotevil: Actor Claims to Leak Data From Okta
- BreachForums user InterSystems: Actor Claims to Leak Data From Cuyahoga Election Audits
VULNERABILITIES
- CVE-2023-6606: An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
- CVE-2023-7192: A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.
BREACHES
- Mother of All Breaches (MOAB): zeeroq.com (226,191,562 Records): Password, Email Address, Username
- Combolist: 'Fresh mix valid.txt' (152,495 Records): Email Address, Password
Tags: DIB, tlp:green